who_need_help/docs/google-play-pre-upload-audit-2026-08-03.md

4.8 KiB

Google Play pre-upload audit — 2026-08-03

This audit separates verified repository/device facts from actions that still require Play Console. It contains no account credentials or signing keys.

Verified locally

  • The selected upload artifact and its checksum are recorded in docs/google-play-release-candidate-2026-08-03.md.
  • Package org.whoneedhelp.mobile, version code 1, version name 0.1.0, minimum SDK 24, and target SDK 37 were verified from the release build.
  • Release unit tests, lint, R8, signing verification, and bundletool validation passed. The release lint report contains no errors or warnings.
  • The native disclosure appears before the location permission flow and explicitly describes precise-location collection and transmission, background use while minimized or not in use, persistent notification, stopping, raw-location deletion, and retained summary evidence.
  • English, Russian, and Ukrainian disclosure and store-listing text describe the same behavior.
  • The public Privacy page identifies Firebase Cloud Messaging and Firebase Installations, the current OpenStreetMap Foundation tile service, and the Android foreground location service behavior.
  • Public Privacy, Terms, Safety, Support, content-reporting, and account-deletion routes exist in the product. Reviewer guidance is recorded in android/play-store/review-access.md.
  • The release APK was installed on the authorised Android 16 physical device. The production home and Safety pages rendered, the production App Link opened MainActivity, and Android reported whoneedhelp.com as verified.
  • The clean PID-scoped application log contains no application crash, AndroidRuntime, TLS/SSL, or WebView load error.
  • No analytics SDK is declared as active in the Android application. Data Safety answers must still describe the behavior of Firebase Messaging/Installations and the app's own server communication.

Verified Play Console state

  • The personal developer identity and contact phone are verified.
  • The Play application exists as app ID 4972430103169452589, package org.whoneedhelp.mobile; it is a free app, not a game, with no ads.
  • Play App Signing was accepted.
  • The exact version-code 1 release AAB is active only on the Internal testing track as 0.1.0 internal verification.
  • Every Play App Signing identity displayed for the accepted artifact was recorded outside Git and reconciled with production Firebase, Google OAuth, and Android App Links.
  • The Play-delivered build passed installer/signature/domain verification, production Google sign-in, verified App Links, production FCM, foreground location while minimized, notification Stop, offline recovery, process recreation, and exact fixture cleanup on the authorised physical phone.

Required before Play review

  • Register and confirm two dedicated non-staff production review accounts with fixed, reusable passwords: one requester/organizer and one helper/participant. Put both credential pairs only in Play Console App access and the operator-controlled password manager.
  • Create their stable synthetic Play review request and activity using scripts/prepare-play-review.sh. Verify both roles and every reviewer instruction from a clean Play-delivered installation.
  • Complete App content: App access, Ads, Content rating, Target audience, News-app declaration, Data Safety, foreground-service location declaration, any target-SDK-37 persistent precise-location declaration actually presented by Play, and the account-deletion URL. Use android/play-store/location-and-fgs-declaration.md; do not claim the app requests ACCESS_BACKGROUND_LOCATION.
  • Record and upload the foreground-service demonstration video from the exact candidate using the prepared evidence script.
  • Recheck the store listing, screenshots, support contact, and privacy-policy URL in Play Console against the prepared files under android/play-store/.

Required after Internal verification

  • Keep the recorded Play App Signing identities, provider reconciliation, and Play-delivered physical-device replay as the Internal-release baseline.
  • Complete the remaining Play App content and listing declarations from the source-controlled material under android/play-store/.
  • Prepare the closed test with at least 12 continuously opted-in testers for at least 14 days before requesting production access. Closed testing and a Production rollout have not been started.

Scope protection

  • Do not upload an older candidate or rebuild after choosing the upload AAB without recording a new source fingerprint and SHA-256.
  • Do not put reviewer passwords, service-account JSON, signing keys, .env files, or Play Console tokens in Git.
  • Do not update or restart the frozen hackathon test project as part of the Play release workflow.